Vulnerabilities (CVE)

Filtered by vendor Jqueryform Subscribe
Filtered by product Jqueryform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24985 1 Jqueryform 1 Jqueryform 2023-08-08 6.0 MEDIUM 8.8 HIGH
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.
CVE-2022-24983 1 Jqueryform 1 Jqueryform 2022-02-25 5.0 MEDIUM 7.5 HIGH
Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.